A critical firmware bug in Coinkite's Coldcard hardware wallets has allowed at least 15 independent attackers to drain up to $130 million (2,055 BTC) from roughly 7,300 addresses. The vulnerability, originating in a March 2021 code change, bypassed the device's hardware randomness chip, reducing key entropy to a guessable 40 bits. While the largest attacker's stash of 1,159 BTC remains unmoved, a smaller exploiter has begun laundering 64 BTC and 200 ETH through Wasabi and Tornado Cash mixers.
Story comments
Loading comments…